CVE-2026-81402 PUBLISHED

DS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File Upload

Assigner: WPScan
Reserved: 26.08.2026 Published: 12.09.2026 Updated: 12.09.2026

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.

Product Status

Vendor Unknown
Product DS Ad Rotator
Versions Default: unknown
  • affected from 0 to 0.8 (incl.)

Credits

  • Huynh Kien Minh finder
  • WPScan coordinator

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE